[SECURITY] bzip2

2008-03-18 Thread Corinna Vinschen
Hi Charles,

I just read that a security problem which has been found in F-Secure
is also a problem for other packages, namely 7zip and bzip2(*).

While this is apparently fixed in our 7zip release 4.57 (called 4.5.7
in the below URL), it's only fixed in bzip2 1.0.5.  We're still at
1.0.3.  Any problem to update?


Thanks,
Corinna

(*) https://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html

-- 
Corinna Vinschen  Please, send mails regarding Cygwin to
Cygwin Project Co-Leader  cygwin AT cygwin DOT com
Red Hat


Re: [SECURITY] bzip2

2008-03-18 Thread Charles Wilson

Corinna Vinschen wrote:

I just read that a security problem which has been found in F-Secure
is also a problem for other packages, namely 7zip and bzip2(*).

While this is apparently fixed in our 7zip release 4.57 (called 4.5.7
in the below URL), it's only fixed in bzip2 1.0.5.  We're still at
1.0.3.  Any problem to update?



Updated.

I'll update mingw-bzip2 within the next few days.

--
Chuck